Netflix Phishing Attack Hides Behind a Functional CAPTCHA Page to Avoid Detection

Stu Sjouwerman | Aug 5, 2020

netflix phishing scamIn an interesting twist, cybercriminals utilize a well-known technology to keep security solutions from identifying a “failed payment” email as being fraudulent.

We’ve all sat there frustrated, being asked to “click on all the boxes that contain” traffic lights, cars, bicycles, or to type in strangely-presented words – all in the name of proving we’re human. CAPTCHA is used by countless websites today as a means of keeping bots out and allowing humans to proceed on a website.

But a recent phishing attack was spotted and analyzed by security researchers at Armorblox, purporting to be from Netflix customer support with a payment issue, was found to use a CAPTCHA landing page before taking the potential victim to a spoofed Netflix logon page.

netflix-login-page-final

This credential scam is elegant and, dare I say, brilliant. What better tool to keep a computer from detecting if the scam’s landing page is legitimate or not than a technology designed to keep computer systems out?

In addition to keeping automated security systems from spotting the fake Netflix logon page, the use of the well-known CAPTCHA adds a layer of familiarity for potential victims, likely making them more prone to continuing through the remainder of the scam.

While organizations usually aren’t concerned about their employee’s Netflix credentials, this same method can just as easily be used to obfuscate spoofed pages designed to steal online business credentials. Educating users with Security Awareness Training on evolving tactics, such as the use of CAPTCHA, can help elevate the employee’s ability to spot a scam and avoid falling for really brilliant tactics, like the ones used in this attack.

Discover Your Organization’s Phish-prone™ Percentage

Ninety-one percent of data breaches begin with spear phishing. Launch our Free Phishing Security Test for up to 100 users to uncover your team's vulnerability and see how your security posture stacks up against industry benchmarks.

Get Your Free Phishing Security Test

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.